Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
Detects the use of non-standard, unusual, or potentially dangerous HTTP methods within Caddy web server logs, which may indicate reconnaissance, web application exploitation, or attempts to abuse server functionalities like WebDAV.
Detects the creation of an executable file named 'stealer.exe' within the Windows Startup folder. This activity is indicative of the Stealer/1.0 malware establishing persistence, ensuring execution upon user logon.
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
This rule monitors process creation and execution events for specific filenames, command line strings, or folder paths that are associated with potentially suspicious or malicious activity. The rule looks for keywords such as ShieldBreak, RoguePlanet, LegacyHive, BlueHammer, RedSun, YellowKey, GreenPlasma, MiniPlasma, and UnDefend.
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
This rule detects potential command and control (C2) activity associated with the CurlRAT malware. It monitors for both the execution of 'curl' or 'curl.exe' processes with command lines containing known C2 domains, and network traffic originating from internal devices directed toward those same domains.
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
Detects potential exploitation of PostgreSQL via logical decoding plugins, specifically targeting CVE-2026-6471. The rule monitors for the PostgreSQL server process spawning suspicious shell utilities or loading modules from locations outside of the expected PostgreSQL library or plugin directories, which is a common indicator of unauthorized code execution.
Detects when the PostgreSQL service process (postgres.exe/postgres/postmaster) loads a shared library (.dll or .so) from a non-standard, user-writable directory (e.g., Temp, AppData, /tmp). This behavior is indicative of potential exploitation of vulnerabilities like CVE-2026-6471, where attackers attempt to load malicious plugins via unvalidated logical decoding plugin paths.
This rule monitors the software inventory for outdated versions of the PostgreSQL database server. It identifies installations where the major and minor versions are below the threshold for current security releases (e.g., v18 < 6, v17 < 11, v16 < 15, v15 < 19, v14 < 24). Running outdated software increases the risk of exploitation of known vulnerabilities.
This rule monitors the software inventory for outdated versions of the PostgreSQL database server. It identifies installations where the major and minor versions are below the threshold for current security releases (e.g., v18 < 6, v17 < 11, v16 < 15, v15 < 19, v14 < 24). Running outdated software increases the risk of exploitation of known vulnerabilities.
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
Detects anomalous activity originating from PostgreSQL processes, including the spawning of shells (cmd, powershell, sh, bash), access to sensitive files (e.g., /etc/shadow, SSH keys), and file creation outside the standard PostgreSQL data directories, which is consistent with the abuse of SQL functionality like pg_read_file() or lo_export().
This rule monitors the software inventory for outdated versions of the PostgreSQL database server. It identifies installations where the major and minor versions are below the threshold for current security releases (e.g., v18 < 6, v17 < 11, v16 < 15, v15 < 19, v14 < 24). Running outdated software increases the risk of exploitation of known vulnerabilities.
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
Page 441 of 1870




